Security Techniques for Virtualized Networks

虚拟化网络的安全技术

基本信息

  • 批准号:
    RGPIN-2018-05323
  • 负责人:
  • 金额:
    $ 2.48万
  • 依托单位:
  • 依托单位国家:
    加拿大
  • 项目类别:
    Discovery Grants Program - Individual
  • 财政年份:
    2020
  • 资助国家:
    加拿大
  • 起止时间:
    2020-01-01 至 2021-12-31
  • 项目状态:
    已结题

项目摘要

The trend to move network management from hardware-based to software-based "virtualized" networks is rapidly getting stronger for economic, technical, and environmental reasons. In virtualized networks, hardware-based network nodes (routers, switches, firewalls, etc.) are replaced with software-based systems that are hosted in virtual machines in the cloud. There is a significant promise of cost reduction and higher resource utilization. Moreover, as this trend relies on software for setup and operation, virtualization is expected to expedite the processes of creating and changing computing and network services. It should also make it easier to create services that were not easily implementable in traditional infrastructures due to cost or scale. This area is of tremendous importance to supporting innovation and economic growth in Canada and elsewhere. Network virtualization will be prevalent in different types of networks: private, public, and hybrid. At the heart of this trend is a significant concern about information security while network elements do not obey the traditional security principles where a physical security perimeter could be established. This proposed research program investigates new techniques for securing virtualized infrastructures from a computer networking perspective. Building on my expertise and my ongoing research program that started with my first Discovery Grant in 2004, the proposed research program will pursue the following distinct themes: Threat modelling and defining an alternative security perimeter for virtual networks. In this theme, we will investigate the creation of a substitute for a security perimeter in software-based virtual networks. Building resilience to attacks into the design of virtualized networks. This gives these networks the ability to sustain attacks and continue to function at a certain level during attacks while other means of defences are being sought. Creating new security evaluation techniques for network applications in virtual networks to be able to assess the security impact of new network applications in these environments. This contributes significantly to fundamental network security research. These defences that emanate from within the network should stop the attacks closer to their sources and reduce attack amplification. Another important benefit of doing this research in creating resilient networking architecture rather than creating a new defence for every type of attack is the prevention of the arms-race situation that we are currently facing. By the time solutions and patches are created, new attacks are appearing again and creating an arms-race like situation. Finally, this program will provide a number of highly qualified personnel with network security skills that are much needed in many industries.
由于经济、技术和环境原因,将网络管理从基于硬件的“虚拟化”网络转移到基于软件的“虚拟化”网络的趋势正在迅速增强。在虚拟化网络中,基于硬件的网络节点(路由器、交换机、防火墙等)被托管在云中虚拟机中的基于软件的系统所取代。降低成本和提高资源利用率具有重大前景。此外,由于这种趋势依赖于软件进行设置和操作,因此虚拟化有望加快创建和更改计算和网络服务的过程。它还应该使创建由于成本或规模而在传统基础设施中不易实现的服务变得更加容易。该领域对于支持加拿大和其他地区的创新和经济增长至关重要。 网络虚拟化将在不同类型的网络中盛行:私有网络、公共网络和混合网络。这一趋势的核心是对信息安全的重大担忧,而网络元素不遵守可以建立物理安全边界的传统安全原则。这项拟议的研究计划从计算机网络的角度研究保护虚拟化基础设施的新技术。 基于我的专业知识和我自 2004 年获得第一笔发现资助以来正在进行的研究项目,拟议的研究项目将追求以下不同的主题: 威胁建模并定义虚拟网络的替代安全边界。在这个主题中,我们将研究在基于软件的虚拟网络中创建安全边界的替代品。 在虚拟化网络的设计中构建抵御攻击的能力。这使得这些网络能够承受攻击并在攻击期间继续在一定水平上运行,同时正在寻求其他防御手段。 为虚拟网络中的网络应用程序创建新的安全评估技术,以便能够评估这些环境中新网络应用程序的安全影响。 这对基础网络安全研究做出了重大贡献。这些来自网络内部的防御措施应该能够阻止攻击靠近其源头并减少攻击放大。进行这项研究创建弹性网络架构而不是为每种类型的攻击创建新的防御措施的另一个重要好处是防止我们目前面临的军备竞赛局面。当解决方案和补丁被创建时,新的攻击再次出现并造成类似军备竞赛的情况。最后,该计划将提供一批具有许多行业急需的网络安全技能的高素质人才。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Matrawy, Ashraf其他文献

Routing Attacks and Mitigation Methods for RPL-Based Internet of Things
  • DOI:
    10.1109/comst.2018.2885894
  • 发表时间:
    2019-01-01
  • 期刊:
  • 影响因子:
    35.6
  • 作者:
    Raoof, Ahmed;Matrawy, Ashraf;Lung, Chung-Horng
  • 通讯作者:
    Lung, Chung-Horng
On the Impact of Network State Collection on the Performance of SDN Applications
  • DOI:
    10.1109/lcomm.2015.2496955
  • 发表时间:
    2016-01-01
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Aslan, Mohamed;Matrawy, Ashraf
  • 通讯作者:
    Matrawy, Ashraf
Economic and Energy Considerations for Resource Augmentation in Mobile Cloud Computing
  • DOI:
    10.1109/tcc.2015.2469665
  • 发表时间:
    2018-01-01
  • 期刊:
  • 影响因子:
    6.5
  • 作者:
    Nir, Manjinder;Matrawy, Ashraf;St-Hilaire, Marc
  • 通讯作者:
    St-Hilaire, Marc

Matrawy, Ashraf的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Matrawy, Ashraf', 18)}}的其他基金

Security Techniques for Virtualized Networks
虚拟化网络的安全技术
  • 批准号:
    RGPIN-2018-05323
  • 财政年份:
    2022
  • 资助金额:
    $ 2.48万
  • 项目类别:
    Discovery Grants Program - Individual
Secure Network Slicing for 5G Services
5G 服务的安全网络切片
  • 批准号:
    543430-2019
  • 财政年份:
    2021
  • 资助金额:
    $ 2.48万
  • 项目类别:
    Collaborative Research and Development Grants
Security Techniques for Virtualized Networks
虚拟化网络的安全技术
  • 批准号:
    RGPIN-2018-05323
  • 财政年份:
    2021
  • 资助金额:
    $ 2.48万
  • 项目类别:
    Discovery Grants Program - Individual
Secure Network Slicing for 5G Services
5G 服务的安全网络切片
  • 批准号:
    543430-2019
  • 财政年份:
    2020
  • 资助金额:
    $ 2.48万
  • 项目类别:
    Collaborative Research and Development Grants
Security Techniques for Virtualized Networks
虚拟化网络的安全技术
  • 批准号:
    RGPIN-2018-05323
  • 财政年份:
    2019
  • 资助金额:
    $ 2.48万
  • 项目类别:
    Discovery Grants Program - Individual
Secure Network Slicing for 5G Services
5G 服务的安全网络切片
  • 批准号:
    543430-2019
  • 财政年份:
    2019
  • 资助金额:
    $ 2.48万
  • 项目类别:
    Collaborative Research and Development Grants
Security Techniques for Virtualized Networks
虚拟化网络的安全技术
  • 批准号:
    RGPIN-2018-05323
  • 财政年份:
    2018
  • 资助金额:
    $ 2.48万
  • 项目类别:
    Discovery Grants Program - Individual
Security in mobile environments
移动环境中的安全
  • 批准号:
    283344-2013
  • 财政年份:
    2017
  • 资助金额:
    $ 2.48万
  • 项目类别:
    Discovery Grants Program - Individual
Threat Modelling in LTE Small Cells Networks
LTE 小蜂窝网络中的威胁建模
  • 批准号:
    501787-2016
  • 财政年份:
    2016
  • 资助金额:
    $ 2.48万
  • 项目类别:
    Engage Grants Program
Security in mobile environments
移动环境中的安全
  • 批准号:
    283344-2013
  • 财政年份:
    2016
  • 资助金额:
    $ 2.48万
  • 项目类别:
    Discovery Grants Program - Individual

相似国自然基金

EstimatingLarge Demand Systems with MachineLearning Techniques
  • 批准号:
  • 批准年份:
    2024
  • 资助金额:
    万元
  • 项目类别:
    外国学者研究基金

相似海外基金

Postdoctoral Fellowship: OPP-PRF: Leveraging Community Structure Data and Machine Learning Techniques to Improve Microbial Functional Diversity in an Arctic Ocean Ecosystem Model
博士后奖学金:OPP-PRF:利用群落结构数据和机器学习技术改善北冰洋生态系统模型中的微生物功能多样性
  • 批准号:
    2317681
  • 财政年份:
    2024
  • 资助金额:
    $ 2.48万
  • 项目类别:
    Standard Grant
RII Track-4:NSF: Design of zeolite-encapsulated metal phthalocyanines catalysts enabled by insights from synchrotron-based X-ray techniques
RII Track-4:NSF:通过基于同步加速器的 X 射线技术的见解实现沸石封装金属酞菁催化剂的设计
  • 批准号:
    2327267
  • 财政年份:
    2024
  • 资助金额:
    $ 2.48万
  • 项目类别:
    Standard Grant
CAREER: Data-Driven Hardware and Software Techniques to Enable Sustainable Data Center Services
职业:数据驱动的硬件和软件技术,以实现可持续的数据中心服务
  • 批准号:
    2340042
  • 财政年份:
    2024
  • 资助金额:
    $ 2.48万
  • 项目类别:
    Continuing Grant
Creating a reflective, assessment workbook for University teachers to enhance teaching techniques and improve student engagement, by incorporating International Baccalaureate (IB) teaching practices
通过纳入国际文凭 (IB) 教学实践,为大学教师创建反思性评估工作簿,以提高教学技巧并提高学生参与度
  • 批准号:
    24K06129
  • 财政年份:
    2024
  • 资助金额:
    $ 2.48万
  • 项目类别:
    Grant-in-Aid for Scientific Research (C)
Developing Advanced Cryptanalysis Techniques for Symmetric-key Primitives with Real-world Public-key Applications
使用现实世界的公钥应用开发对称密钥原语的高级密码分析技术
  • 批准号:
    24K20733
  • 财政年份:
    2024
  • 资助金额:
    $ 2.48万
  • 项目类别:
    Grant-in-Aid for Early-Career Scientists
Development of new molecular self-temperature sensing techniques using luminescence-absorption hybrid thermometry
利用发光-吸收混合测温法开发新型分子自温度传感技术
  • 批准号:
    24K17691
  • 财政年份:
    2024
  • 资助金额:
    $ 2.48万
  • 项目类别:
    Grant-in-Aid for Early-Career Scientists
Novel techniques of percutaneous sonography-guided surgical operations (SonoSurgery
经皮超声引导外科手术新技术(SonoSurgery
  • 批准号:
    10087309
  • 财政年份:
    2024
  • 资助金额:
    $ 2.48万
  • 项目类别:
    Collaborative R&D
ERI: SDR Beyond Radio: Enabling Experimental Research in Multi-Node Optical Wireless Networks via Software Defined Radio Tools and Techniques
ERI:超越无线电的 SDR:通过软件定义无线电工具和技术实现多节点光无线网络的实验研究
  • 批准号:
    2347514
  • 财政年份:
    2024
  • 资助金额:
    $ 2.48万
  • 项目类别:
    Standard Grant
CRII: SHF: Embedding techniques for mechanized reasoning about existing programs
CRII:SHF:现有程序机械化推理的嵌入技术
  • 批准号:
    2348490
  • 财政年份:
    2024
  • 资助金额:
    $ 2.48万
  • 项目类别:
    Standard Grant
Oxidation Pathways and Radicals at the Gas-Particle Interface Using Surface-Sensitive Techniques
使用表面敏感技术研究气体-颗粒界面处的氧化途径和自由基
  • 批准号:
    2331523
  • 财政年份:
    2024
  • 资助金额:
    $ 2.48万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了